work-mvp
Warn
Audited by Socket on Mar 21, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose matches a dev-workflow orchestration skill, and there is no clear credential harvesting or exfiltration. However, the skill’s core behavior depends on an unverified `lev` binary and passes session-generated steps into that executor, creating a high install/execution-trust risk disproportionate to the limited provenance evidence provided.
Confidence: 81%Severity: 78%
Audit Metadata